Art.25
EU AI Act Guide › Chapter III — High-Risk AI Systems › Article 25

Article 25 — Responsibilities Along the AI Value Chain

SME Key SME Relevant ~3 min read · 532 words

Article 25 contains one of the most important — and most frequently misunderstood — provisions in the entire Act. It defines the circumstances under which a distributor, importer, deployer, or third party becomes legally reclassified as a provider, inheriting all provider obligations. If you modify AI, rebrand it, or change its purpose, read this article carefully.

! High compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

When downstream parties become providers

Article 25 addresses the allocation of responsibility along the AI supply chain. It establishes three specific circumstances under which a party that is not the original developer of an AI system — a distributor, importer, deployer, or third party — is reclassified as a provider and must therefore comply with all provider obligations under Article 16. This article is critical for anyone who modifies, rebrands, or repurposes AI systems they did not originally build.

WHAT IT SAYS

Three triggers that make you a provider

  • Trigger 1 — Rebranding: Any party that puts their own name or trademark on a high-risk AI system already on the market becomes the provider of that system and assumes all provider obligations
  • Trigger 2 — Substantial modification: Any party that makes a substantial modification to a high-risk AI system already on the market — such that it remains high-risk — becomes the new provider
  • Trigger 3 — Purpose change: Any party that modifies the intended purpose of an AI system that was not high-risk, in a way that makes it high-risk, becomes the provider of that newly high-risk system
  • When reclassification occurs, the original provider is no longer considered the provider of that specific system for regulatory purposes — the new provider takes on all obligations
  • The original provider must cooperate with the new provider and supply necessary information and technical access to enable compliance
  • Product manufacturers who integrate a high-risk AI system as a safety component into their regulated product are also considered providers of the AI system

WHO IS AFFECTED

Anyone who modifies, rebrands, or repurposes AI systems

  • Companies that white-label AI systems under their own brand — they become providers the moment they apply their name
  • Businesses that fine-tune, customise, or substantially modify third-party AI models for specific use cases
  • Organisations that take a general-purpose AI system and deploy it in a high-risk context it was not originally designed for
  • Product manufacturers who embed third-party high-risk AI as a component in their regulated products

WHAT IT MEANS FOR SMES

The three questions every SME using third-party AI must answer

  • Question 1: Are you putting your name or logo on a third-party AI system? If yes, you are now the provider — with full provider obligations including conformity assessment, CE marking, and technical documentation
  • Question 2: Are you making substantial modifications to a third-party AI system? The Act does not precisely define ‘substantial’ but changes to core functionality, training data, or intended use cases are likely to qualify
  • Question 3: Are you deploying a general-purpose AI system in a high-risk context it was not designed for? If so, you have created a new high-risk AI system and are its provider
  • Many SMEs are inadvertently becoming providers through white-labelling and customisation without realising it — this article is the one that catches them
  • If you are uncertain whether your modifications constitute ‘substantial’ modification, document your reasoning carefully — this documentation will be your defence if the question is ever raised by a regulator

Related Articles

← Previous Art. 24 — Obligations of Distributors Next → Art. 26 — Obligations of Deployers of High-Risk AI Systems